CVE-2026-24686
Vulnerability Summary
Timeline
Description
go-tuf is a Go implementation of The Update Framework (TUF). go-tuf's TAP 4 Multirepo Client uses the map file repository name string (`repoName`) as a filesystem path component when selecting the local metadata cache directory. Starting in version 2.0.0 and prior to version 2.4.1, if an application accepts a map file from an untrusted source, an attacker can supply a `repoName` containing traversal (e.g., `../escaped-repo`) and cause go-tuf to create directories and write the root metadata file outside the intended `LocalMetadataDir` cache base, within the running process's filesystem permissions. Version 2.4.1 contains a patch.
CVSS Metrics
- v3.1•MEDIUM•Score: 4.7CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS Trends
Current EPSS score: 0.22%• Percentile: 13%
Techniques & Countermeasures
- CWE-22•Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Affected Systems
- chainguard•buildkitd
< 0.27.1-r3
- chainguard•buildkitd-fips
< 0.27.1-r0
- chainguard•cg
< 0.2.202-r0
- chainguard•chainctl
< 0.2.206-r0
- chainguard•commercial-kyverno-1.15
all
- chainguard•commercial-kyverno-background-controller-1.15
all
- chainguard•commercial-kyverno-cleanup-controller-1.15
all
- chainguard•commercial-kyverno-reports-controller-1.15
all
- chainguard•commercial-kyvernopre-1.15
all
- chainguard•cosign
< 3.0.4-r2
- chainguard•cosign-fips
< 3.0.4-r3
- chainguard•crossplane-1.20
< 1.20.5-r1
- chainguard•crossplane-2.0
< 2.0.7-r0
- chainguard•crossplane-2.1
< 2.1.4-r0
- chainguard•crossplane-fips-1.20
< 1.20.5-r4
- chainguard•crossplane-fips-2.0
< 2.0.7-r0
- chainguard•crossplane-fips-2.1
< 2.1.4-r0
- chainguard•dockerd-29
< 29.2.1-r0
- chainguard•falcoctl
< 0.12.2-r0
- chainguard•falcoctl-fips
< 0.12.2-r0
- chainguard•flux-source-controller
< 1.7.4-r6
- chainguard•flux-source-controller-fips
< 1.7.4-r6
- chainguard•gh
< 2.86.0-r1
- chainguard•gitsign
< 0.14.0-r0
- chainguard•goreleaser
< 2.13.3-r4
- chainguard•image-factory
< 1.0.2-r0
- chainguard•image-factory-fips
< 1.0.2-r0
- chainguard•ko
< 0.18.1-r2
- chainguard•ko-fips
< 0.18.1-r2
- chainguard•kubescape
< 4.0.0-r0
- chainguard•kyverno-1.13
all
- chainguard•kyverno-1.14
all
- chainguard•kyverno-1.15
all
- chainguard•kyverno-1.16
< 1.16.3-r2
- chainguard•kyverno-background-controller-1.13
all
- chainguard•kyverno-background-controller-1.14
all
- chainguard•kyverno-background-controller-1.15
all
- chainguard•kyverno-background-controller-1.16
< 1.16.3-r2
- chainguard•kyverno-background-controller-fips-1.13
all
- chainguard•kyverno-background-controller-fips-1.14
all
- chainguard•kyverno-background-controller-fips-1.15
all
- chainguard•kyverno-background-controller-fips-1.16
< 1.16.3-r3
- chainguard•kyverno-cleanup-controller-1.13
all
- chainguard•kyverno-cleanup-controller-1.14
all
- chainguard•kyverno-cleanup-controller-1.15
all
- chainguard•kyverno-cleanup-controller-1.16
< 1.16.3-r2
- chainguard•kyverno-cleanup-controller-fips-1.13
all
- chainguard•kyverno-cleanup-controller-fips-1.14
all
- chainguard•kyverno-cleanup-controller-fips-1.15
all
- chainguard•kyverno-cleanup-controller-fips-1.16
< 1.16.3-r3
Showing first 50 affected entries in server-rendered view.
References (6)
- https://github.com/theupdateframework/go-tuf/security/advisories/GHSA-jqc5-w2xx-5vq4
- https://github.com/theupdateframework/go-tuf/commit/d361e2ea24e427581343dee5c7a32b485d79fcc0
- https://github.com/theupdateframework/go-tuf
- https://nvd.nist.gov/vuln/detail/CVE-2026-24686
- https://security-tracker.debian.org/tracker/CVE-2026-24686
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/24xxx/CVE-2026-24686.json